Selective Encryption for Processing-in-Memory
Abstract
Selective encryption for processing-in-memory is described. In implementations, an encryption scheme used by a host processing device is different than an encryption scheme used by a memory device coupled to the host processing device. By designating data elements for encryption using a memory encryption scheme, the host processing device offloads encryption of the data elements to a memory device. Offloading encryption to the memory device enables the memory device to retrieve encrypted data from memory, decrypt the data, perform one or more processing-in-memory operations on the decrypted data using a processing-in-memory component of the memory device. Following completion of processing-in-memory operations, the memory device re-encrypts the data and stores the re-encrypted data in memory without transmitting the data to the host processing device.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A device comprising:
a memory; and cryptographic circuitry configured to:
receive, from a host device, a first encrypted data element and a second data element designated for encryption by the cryptographic circuitry;
encrypt the second data element; and
store, in the memory, the first encrypted data element and the second data element that is encrypted by the cryptographic circuitry.
2 . The device of claim 1 , wherein the first encrypted data element and the second data element are encrypted by an interface encryption, the cryptographic circuitry further configured to:
decrypt the interface encryption from the first encrypted data element before storing the first encrypted data element; and decrypt the interface encryption from the second data element before encrypting and storing the second data element.
3 . The device of claim 1 , further comprising an in-memory processor processing-in-memory component configured to execute a processing-in-memory command by:
retrieving the second data element from the memory; decrypting the second data element; performing at least one processing-in-memory operation using the second data element; re-encrypting the second data element; and storing the re-encrypted second data element in the memory.
4 . The device of claim 3 , wherein performing the at least one processing-in-memory operation comprises modifying the second data element before re-encrypting the second data element.
5 . The device of claim 3 , wherein the at least one processing-in-memory operation is performed independent of communicating the second data element to the host device.
6 . The device of claim 3 , wherein the at least one processing-in-memory operation is performed independent of the host device decrypting the second data element.
7 . The device of claim 1 , wherein the first encrypted data element and the second data element are elements of a single row of data in the memory.
8 . The device of claim 1 , the cryptographic circuitry further configured to receive an indication that the second data element is designated for encryption by the cryptographic circuitry as part of a row activation command from the host device.
9 . The device of claim 1 , wherein the first encrypted data element is encrypted using a first encryption key and the second data element is encrypted by the cryptographic circuitry using a second encryption key that is different than the first encryption key.
10 . The device of claim 9 , wherein the host device and the device are connected by an interface and data communicated via the interface is encrypted using a third encryption key that is different than the first encryption key and different than the second encryption key.
11 . The device of claim 1 , the cryptographic circuitry further configured to receive, from the host device, an encryption key for encrypting data in the memory and encrypt the second data element using the encryption key.
12 . The device of claim 1 , further comprising key generation circuitry disposed in the memory or near the memory, the key generation circuitry configured to generate a memory encryption key, wherein the cryptographic circuitry encrypts the second data element using the memory encryption key.
13 . The device of claim 1 , wherein the cryptographic circuitry is further configured to:
receive an indication that memory-side encryption is to be applied to the second data element; and
based on the indication and prior to receipt of the second data element, perform a first portion of encryption operations that are used to encrypt the second data element.
14 . A system comprising:
a host device that includes at least one processing unit configured to:
encrypt a first data element using a host encryption key; and
transmit the first data element and a second data element to a memory device;
an interface connecting the host device and the memory device; and the memory device that includes a memory and an in-memory processor, the memory device configured to: encrypt the second data element using a memory encryption key; and store, in the memory, the first data element as encrypted by the host device and the second data element as encrypted by the memory device.
15 . The system of claim 14 , wherein the host encryption key and the memory encryption key are different encryption keys.
16 . The system of claim 14 , wherein the at least one processing unit is configured to encrypt the first data element using a first algorithm and the memory device is configured to encrypt the second data element using a second algorithm that is different than the first algorithm.
17 . The system of claim 14 , wherein the at least one processing unit is further configured to encrypt the first data element and the second data element with an interface encryption, wherein the memory device is further configured to remove the interface encryption from the first data element and the second data element before storing the first data element in the memory and before encrypting and storing the second data element in the memory.
18 . The system of claim 15 , wherein the at least one processing unit is further configured to transmit a row activation command to the memory device via the interface and instruct, based on a bit in the row activation command, the memory device to encrypt the second data element using the memory encryption key.
19 . A method comprising:
encrypting, by a processing device, a first data element using a first encryption key; transmitting, by the processing device and to a memory device, the first data element as encrypted by the processing device; transmitting, by the processing device and to the memory device, a second data element; and causing, by the processing device:
storage of the first data element in the memory device as encrypted by the processing device;
encryption, by memory device, of the second data element using a second encryption key; and
storage of the second data element in the memory device as encrypted by the memory device.
20 . The method of claim 19 , further comprising executing a processing-in-memory command using an in-memory processor of the memory device and the second data element by:
decrypting the second data element using the second encryption key; performing at least one operation using the second data element; re-encrypting the second data element using the second encryption key; and storing the re-encrypted second data element in the memory device.Join the waitlist — get patent alerts
Track US2026081773A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.